If you handle defense contracts, you've probably felt the whiplash. For years, the message was clear: prepare for mandatory third-party CMMC assessments or lose your place in the supply chain. Then, on July 13, 2026, the Department of War suspended Phase II—the very requirement everyone had been racing toward.
It's tempting to read that headline as a reprieve. It isn't. Phase I self-assessment requirements are still active. DFARS clauses still bind you to NIST SP 800-171. Your SPRS score still matters, and a senior official still has to affirm it every year. The pause changed one piece of the timeline, not the underlying obligation to protect sensitive defense information.
This post breaks down what CMMC compliance actually requires right now—the levels, the controls, SPRS scoring, POA&M rules, and the flowdown responsibilities that catch so many contractors off guard. More importantly, it explains what to do during the Phase II pause so you're not scrambling when assessments resume. If and when they resume.
What Is CMMC Compliance?
CMMC is the DOW's framework for verifying that defense contractors and subcontractors implement the cybersecurity practices needed to protect FCI and CUI. CMMC 2.0 organizes these requirements into three tiered levels aligned to NIST SP 800-171 and NIST SP 800-172. Depending on the sensitivity of the information you handle, compliance is verified through annual self-assessments or third-party audits.
The framework exists for one reason: the Defense Industrial Base is a constant target for cyberattacks, and every contractor that touches sensitive data is a potential entry point. CMMC standardizes the baseline so a small subcontractor can't become the weak link that compromises a national security program.
Update — July 2026
The Department of War has suspended CMMC Phase II (C3PAO) certification, previously set for November 10, 2026, and launched a 60-day reform review. DFARS 7012, NIST 800-171 Rev. 2, and your SPRS score all still apply. Shifting weight back onto self-attestation raises your False Claims Act exposure, and the requirement to prove compliance stays in force. The review reconsiders how that verification happens.
What Changed in 2026: The Phase II Pause
On July 13, 2026, the DOW suspended Phase II—the mandatory third-party Level 2 assessments conducted by accredited C3PAOs (CMMC Third-Party Assessment Organizations)—for a subset of acquisitions. The suspension came with a 60-day reform review aimed at lowering barriers for small and non-traditional businesses.
Here's what did not go away:
- Phase I self-assessments remain active. Contractors must complete annual self-assessments and submit results with senior-official affirmations into the Supplier Performance Risk System (SPRS).
- DFARS 252.204-7012 continues to bind contractors to NIST SP 800-171.
- DFARS 252.204-7021, effective October 1, 2025, requires a CMMC certificate by contract award for applicable solicitations—maintained for the contract's duration and flowed down to subcontractors.
- SPRS score submission and the underlying 800-171 obligations stay enforceable.
Treat the pause as a holiday and you take on real contractual and legal risk. The contractors who come out ahead will keep their System Security Plan (SSP) current, maintain evidence continuously, and keep their SPRS score accurate—as if an assessment could land tomorrow.
Who Needs CMMC Compliance?
CMMC applies to every organization in the DOW supply chain that processes, stores, or transmits FCI or CUI. That includes subcontractors. Two information types drive your required level:
- FCI (Federal Contract Information): Information provided by or generated for the government under a contract, not intended for public release.
- CUI (Controlled Unclassified Information): Information that law, regulation, or government-wide policy requires to be safeguarded using established controls.
Prime contractors carry an extra burden. They must assess their entire environment and flow CMMC requirements down to subcontractors handling the same type of information. A subcontractor that only receives FCI needs Level 1. One that receives CUI needs Level 2 or higher. Primes are increasingly verifying subcontractor compliance before award, which makes SPRS visibility and a documented SSP critical at every tier.
The Three CMMC Levels Explained
CMMC 2.0 uses three levels, each raising the bar on rigor and verification.
Level | Focus | Aligned Standard | How Compliance Is Verified |
Level 1 | Basic cyber hygiene; contractors handling FCI | FAR 52.204-21 (17 practices) | Annual self-assessment + senior-official affirmation in SPRS |
Level 2 | Protection of CUI | NIST SP 800-171 (110 practices) | Self-assessment (subset) OR triennial C3PAO assessment |
Level 3 | Highest-priority national security programs | Subset of NIST SP 800-172 | Triennial government-led assessment (requires certified Level 2 first) |
Level 2 is where most defense contractors live. It's the most operationally complex, evidence-intensive tier—and the one where preparation gaps most often cost organizations contracts. If you handle CUI, this is your level, and it demands all 110 practices from NIST SP 800-171 across 14 control families.
What Assessors Actually Look For at Level 2
Implementing a control isn't enough. Assessors evaluate whether it operates consistently over time. They want three things for every practice: policies (intent), procedures (method), and records (proof).
A policy document with no operational records—no logs, no completed access reviews, no training certifications, no scan results—is a control gap waiting to become an audit finding. Evidence is the product. That's why continuous evidence collection beats a pre-audit scramble every time. Evidence gathered the week before an assessment doesn't demonstrate the consistent operation that Level 2 requires.
How SPRS Scoring Works and How to Prepare
The Supplier Performance Risk System (SPRS) is where you submit your self-assessment score against NIST SP 800-171's 110 practices.
The math is straightforward:
- You start at 110 points.
- Each unimplemented practice deducts a weighted value—practices range from 1 to 5 points based on security impact.
- A perfect score is 110. Anything lower means some practices aren't fully implemented.
- Negative scores are possible and signal serious gaps.
To prepare for your SPRS affirmation, complete a full self-assessment against all 110 practices, document your scoring methodology and supporting evidence, and make sure your SSP reflects your actual environment rather than an aspirational one. Track every unimplemented practice in a POA&M, have a senior official review and affirm the submission annually, then submit through the SPRS portal.
One warning worth taking seriously: submitting an inflated SPRS score exposes you to False Claims Act liability. The DOJ's Civil Cyber-Fraud Initiative has pursued FCA cases against organizations that knowingly misrepresented their cybersecurity posture on federal contracts. Score conservatively and document how you got there. Accurate scoring is a legal obligation, not a best practice.
POA&M Rules: What You Can and Can't Defer
A Plan of Action and Milestones (POA&M) tracks cybersecurity weaknesses, remediation steps, owners, and target completion dates. CMMC allows limited POA&M use—but it's not a blank check.
- Certain highest-weighted practices cannot go on a POA&M. They must be implemented before certification or contract award.
- POA&M items need realistic, time-boxed milestones. Indefinite deferrals aren't compliant.
- Every item must trace to a specific NIST SP 800-171 practice with a documented plan for closure.
- Review and update POA&M status regularly, not just at assessment time.
- Retain close-out evidence for each completed item.
The most common failures? Listing items without target dates, failing to close them before the assessment window, parking ineligible practices on the POA&M, and losing close-out evidence between review cycles.
What Does CMMC Compliance Cost?
Costs vary based on your size, current maturity, the number of systems in scope, and whether a C3PAO assessment is required. Level 2 self-assessment preparation typically runs from $30,000 to well over $150,000. A C3PAO assessment, when required, adds $20,000 to $100,000+ on top of preparation—and that's assessment fees alone.
The single biggest lever on total cost is your evidence posture heading into an assessment. When your evidence is organized, current, and mapped to specific controls, preparation labor drops substantially. When it's scattered across spreadsheets and shared drives, every assessment cycle becomes an expensive fire drill.
The Flowdown Reality for Primes and Subcontractors
Prime contractors are responsible for ensuring subcontractors handling CUI meet the appropriate CMMC level. This isn't optional, and primes are enforcing it before subcontract award.
If you're a prime, identify every subcontractor that will receive CUI or FCI, determine the right level for each, include DFARS 252.204-7021 in your subcontract language, and request SPRS scores and SSP availability before award. Build a process for ongoing verification.
If you're a subcontractor, don't wait for a contract requirement to start preparing. Your SPRS score and SSP readiness are visible to primes, and increasingly they'll ask for both before you even know a solicitation is out. Understand exactly which CUI you receive, how you store it, and whether your environment meets the applicable level.
What to Do During the Phase II Pause
This is the question every contractor is asking: if third-party assessments are suspended, what do we do now?
Stay assessment-ready. That's the whole answer, and it comes down to a few disciplined habits:
- Maintain your annual self-assessment cadence.
- Keep your SSP and POA&M current after any system, personnel, or process change.
- Ensure your SPRS score reflects your actual state.
- Continue evidence collection year-round, not in a pre-audit sprint.
- Monitor DOW rulemaking—CMMC is in active development, and requirements will shift as NIST SP 800-171 and 800-172 evolve.
Point-in-time preparation produces point-in-time results. Contracts last longer than audit cycles, and the reform review will eventually resolve. The organizations that keep their programs running through the pause won't fall behind when Phase II returns.
How to Stay Audit-Ready Without the Manual Grind
Manual CMMC programs accumulate debt fast. Spreadsheet tracking, screenshot gathering, and email-based evidence requests eat the hours your team needs for actual remediation.
Drata's platform supports continuous CMMC readiness across the areas that matter most:
Drata doesn’t store or process CUI and doesn’t hold FedRAMP Moderate authorization, so CUI stays in your compliant environment — GCC High, AWS GovCloud, Azure Government, or a secure on-prem system. What Drata continuously monitors is the non-CUI evidence that proves those controls are working: access logs, system configurations, training records, and policy acknowledgments.
- Continuous control monitoring validates that safeguards stay in place between assessments, flagging drift before it becomes a finding.
- A dedicated CMMC framework mapping aligns platform capabilities to CMMC 2.0 Levels 1 and 2 practices, so control coverage stays visible in real time.
- Automated evidence collection cuts the manual overhead of gathering, organizing, and retaining audit artifacts throughout the year.
- Access review automation supports least-privilege enforcement and the recurring reviews embedded across the Access Control domain.
- Multi-framework control reuse lets teams already pursuing SOC 2 or ISO 27001 reuse overlapping controls for CMMC, cutting duplicated effort.
- Trust Center shares your compliance posture securely with government stakeholders, primes, and subcontractor partners.
The goal isn't to replace the work CMMC requires. It's to make continuous compliance sustainable, so your evidence is current whenever a contract, prime, or assessor asks for proof.
83%
83% of organizations report moderate or major delays caused by manual compliance work — and 53% dedicate the equivalent of a full-time employee exclusively to evidence collection.
RegScale State of CCM Report 2026Your Next Step Toward Continuous CMMC Readiness
CMMC isn't going away. The Phase II pause bought contractors time, not a pass. The programs that treat compliance as a living, continuous state—current SSP, accurate SPRS score, evidence collected all year—will move faster when assessments resume and win more work in the meantime.
Start by mapping your current controls to all 110 NIST SP 800-171 practices, scoring your SPRS baseline honestly, and building a POA&M for every gap. Then commit to a cadence that keeps that evidence fresh.
Ready to make continuous CMMC compliance operationally sustainable? Book a demo with Drata to see how automated evidence collection and continuous monitoring keep your program audit-ready.
FAQs About CMMC Compliance
Is CMMC Phase II still happening?
Phase II—mandatory C3PAO third-party assessments for a subset of Level 2 acquisitions—was suspended on July 13, 2026. Phase I self-assessment requirements remain in force. Monitor the DOW CMMC page (dodcio.defense.gov/CMMC) and the Federal Register for updated timelines.
What should we do right now during the Phase II pause?
Maintain your self-assessment cadence, keep your SSP and POA&M current, ensure your SPRS score is accurate, and continue collecting evidence as if an assessment could happen at any time. The pause affects one subset of assessment requirements—not your underlying compliance obligations.
What are CMMC Level 2 requirements?
Level 2 requires implementing all 110 practices from NIST SP 800-171 across 14 control families. Compliance is verified through self-assessment for some acquisitions or a triennial third-party assessment by an accredited C3PAO.
What is an SPRS score?
Your SPRS (Supplier Performance Risk System) score represents your self-assessed implementation status against NIST SP 800-171. You start at 110 points and deduct a weighted value for each unimplemented practice. Scores and senior-official affirmations must be submitted annually.
Do subcontractors need CMMC?
Yes. If a subcontractor handles CUI or FCI, CMMC requirements flow down from the prime contractor. The applicable level depends on what type of information the subcontractor processes, stores, or transmits.